Skip to main content

libid_contracts/bindings/
identity.rs

1//! Bindings for the identity-names stack (`solidity/contracts/identity/`):
2//! `IdentityNames`, the per-platform verifiers, and the Google JWKS trust
3//! list.
4
5/// Bindings for `identity/IdentityNames.sol`.
6///
7/// `Rules` mirrors `HandleNormalizer.Rules` — the normalization rules the
8/// contract stores per platform. Platform ids are `keccak256` of the
9/// platform's domain string.
10#[allow(clippy::too_many_arguments, unused_attributes)]
11mod names_inner {
12    use alloy::sol;
13
14    sol! {
15        #[sol(rpc)]
16        interface IdentityNames {
17            #[derive(Debug, serde::Serialize, serde::Deserialize)]
18            struct Rules {
19                uint16 maxLength;
20                bool stripLeadingAt;
21                bool isEmail;
22                bool allowUnderscore;
23                bool allowHyphen;
24            }
25
26            function initialize(address owner_) external;
27            function setPlatform(
28                bytes32 platformId,
29                address verifier,
30                uint64 maxFutureObservation,
31                Rules calldata rules
32            ) external;
33
34            function verifierOf(bytes32 platformId) external view returns (address);
35            function bind(bytes32 platformId, bytes calldata proof, bool publishName) external;
36            function unpublish(bytes32 platformId) external;
37            function resolveId(bytes32 platformId, string calldata userId) external view returns (address);
38            function resolveHandle(bytes32 platformId, string calldata handle) external view returns (address);
39            function resolvePair(bytes32 platformId, string calldata handle, string calldata userId) external view returns (address);
40            function reverseOf(address wallet, bytes32 platformId) external view returns (string memory);
41            function primaryOf(address wallet, bytes32 platformId) external view returns (string memory);
42
43            event HandleRetired(bytes32 indexed platformId, bytes32 indexed handleNode, address indexed owner);
44            event PlatformConfigured(bytes32 indexed platformId, address verifier);
45            event NameUnpublished(address indexed owner, bytes32 indexed platformId);
46        }
47    }
48}
49
50pub use names_inner::IdentityNames;
51
52/// The claim every identity verifier returns
53/// (`identity/IIdentityVerifier.sol`).
54#[allow(clippy::too_many_arguments, unused_attributes)]
55mod verifier_iface_inner {
56    use alloy::sol;
57
58    sol! {
59        #[sol(rpc)]
60        interface IIdentityVerifier {
61            #[derive(Debug, serde::Serialize, serde::Deserialize)]
62            struct IdentityClaim {
63                string userId;
64                string handle;
65                address target;
66                uint64 observedAt;
67            }
68
69            function verify(bytes calldata proof) external view returns (IdentityClaim memory claim);
70            function platformName() external view returns (string memory);
71        }
72    }
73}
74
75pub use verifier_iface_inner::IIdentityVerifier;
76
77/// Bindings for `identity/XIdentityVerifier.sol`.
78#[allow(clippy::too_many_arguments, unused_attributes)]
79mod x_verifier_inner {
80    use alloy::sol;
81
82    sol! {
83        #[sol(rpc)]
84        interface XIdentityVerifier {
85            #[derive(Debug, serde::Serialize, serde::Deserialize)]
86            struct MeAttestation {
87                bytes32 bearerHash;
88                uint32 bearerRangeStart;
89                uint32 bearerRangeEnd;
90                bytes sentRevealed;
91                uint32 sentPrefixEnd;
92                uint32 sentSuffixEnd;
93                bytes recvRevealed;
94                string handle;
95                string userId;
96                address sessionAddr;
97                uint64 timestamp;
98                bytes notarySignature;
99            }
100
101            #[derive(Debug, serde::Serialize, serde::Deserialize)]
102            struct XProof {
103                bytes proof;
104                bytes32[] publicInputs;
105                MeAttestation meAttest;
106            }
107
108            #[derive(Debug, serde::Serialize, serde::Deserialize)]
109            struct ResponseShape {
110                string platformName;
111                string endpoint;
112                string handlePrefix;
113                string idPrefix;
114                string idSuffix;
115            }
116
117            function initialize(
118                address owner_,
119                address notary_,
120                address honkVerifier_,
121                ResponseShape calldata shape_
122            ) external;
123            function setTrust(address notary_, address honkVerifier_) external;
124            function setResponseShape(ResponseShape calldata shape_) external;
125
126            function platformName() external view returns (string memory);
127            function endpoint() external view returns (string memory);
128            function handlePrefix() external view returns (string memory);
129            function idPrefix() external view returns (string memory);
130            function idSuffix() external view returns (string memory);
131        }
132    }
133}
134
135pub use x_verifier_inner::XIdentityVerifier;
136
137/// Bindings for `identity/GitHubIdentityVerifier.sol`.
138#[allow(clippy::too_many_arguments, unused_attributes)]
139mod github_verifier_inner {
140    use alloy::sol;
141
142    sol! {
143        #[sol(rpc)]
144        interface GitHubIdentityVerifier {
145            #[derive(Debug, serde::Serialize, serde::Deserialize)]
146            struct FullTlsProof {
147                bytes notarySignature;
148                bytes backendSignature;
149                address userAddress;
150                address walletAddress;
151                bytes32 domainHash;
152                bytes32 clientRandom;
153                bytes32 serverRandom;
154                bytes serverEphemeralKey;
155                bytes32 transcriptRoot;
156                uint256 timestamp;
157                bytes32[] domainPath;
158                bytes32[] usernamePath;
159                bytes32[] endpointPath;
160                bytes32[] idPath;
161            }
162
163            /// The proof plus the strings it is checked against. A verifier
164            /// takes one `bytes` argument, so they travel together.
165            #[derive(Debug, serde::Serialize, serde::Deserialize)]
166            struct GitHubProof {
167                FullTlsProof tls;
168                string domain;
169                string handle;
170                string userId;
171                string endpoint;
172            }
173
174            #[derive(Debug, serde::Serialize, serde::Deserialize)]
175            struct ResponseShape {
176                string endpoint;
177                string handlePrefix;
178                string idPrefix;
179                string idSuffix;
180            }
181
182            function initialize(
183                address owner_,
184                address notary_,
185                address backend_,
186                ResponseShape calldata shape_
187            ) external;
188            function setSigners(address notary_, address backend_) external;
189            function setResponseShape(ResponseShape calldata shape_) external;
190
191            function notary() external view returns (address);
192            function backend() external view returns (address);
193            function platformName() external view returns (string memory);
194        }
195    }
196}
197
198pub use github_verifier_inner::GitHubIdentityVerifier;
199
200/// Bindings for `identity/GoogleIdentityVerifier.sol`.
201#[allow(clippy::too_many_arguments, unused_attributes)]
202mod google_verifier_inner {
203    use alloy::sol;
204
205    sol! {
206        #[sol(rpc)]
207        interface GoogleIdentityVerifier {
208            /// One proof over a Google-signed id_token. Identity binds on
209            /// `sub` (the immutable Google account id).
210            #[derive(Debug, serde::Serialize, serde::Deserialize)]
211            struct UserProof {
212                bytes honkProof;
213                bytes32[] publicInputs;
214                string email;
215                address sessionKey;
216                string sub;
217            }
218
219            function initialize(address owner_, address honkVerifier_, address jwksRoots_) external;
220            function setTrust(address honkVerifier_, address jwksRoots_) external;
221
222            function honkVerifier() external view returns (address);
223            function jwksRoots() external view returns (address);
224            function platformName() external view returns (string memory);
225        }
226    }
227}
228
229pub use google_verifier_inner::GoogleIdentityVerifier;
230
231/// Bindings for `identity/IdentityJwksRoots.sol` — the naming system's own
232/// Google JWKS trust list. Starts EMPTY: Google names bind only once a
233/// notarized reading of Google's JWKS has landed here.
234#[allow(clippy::too_many_arguments, unused_attributes)]
235mod jwks_roots_inner {
236    use alloy::sol;
237
238    sol! {
239        #[sol(rpc)]
240        interface IdentityJwksRoots {
241            #[derive(Debug, serde::Serialize, serde::Deserialize)]
242            struct NotarizedJwksProof {
243                bytes notarySignature;
244                bytes32 domainHash;
245                bytes32 clientRandom;
246                bytes32 serverRandom;
247                bytes serverEphemeralKey;
248                bytes32 transcriptRoot;
249                uint256 timestamp;
250                bytes32[] domainPath;
251                bytes32[] endpointPath;
252            }
253
254            #[derive(Debug, serde::Serialize, serde::Deserialize)]
255            struct JwkClaim {
256                bytes jwkBytes;
257                bytes32[] jwkPath;
258                bytes kid;
259                bytes nB64url;
260            }
261
262            function initialize(address owner_, address initialNotary) external;
263            function addNotary(address n) external;
264            function removeNotary(address n) external;
265            function untrustModulus(bytes32 modulusHash) external;
266            function rotate(NotarizedJwksProof calldata proof, JwkClaim[] calldata claims) external;
267            function trustedHashExpiresAt(bytes32 modulusHash) external view returns (uint256);
268
269            event ModulusRotated(bytes32 indexed kidHash, string kid, bytes32 modulusHash, uint256 expiresAt);
270            event NotaryAdded(address indexed notary);
271            event NotaryRemoved(address indexed notary);
272            event ModulusUntrusted(bytes32 indexed modulusHash);
273        }
274    }
275}
276
277pub use jwks_roots_inner::IdentityJwksRoots;